kGrange | 12 years ago | on: Why I don't touch crypto
kGrange's comments
kGrange | 12 years ago | on: Feds, We Need Some Time Apart
> recent revelations have made many in the community uncomfortable about this relationship.
They just don't want to deal with fed vs. non-fed tensions at the con. Maybe they're afraid fights would break out.
kGrange | 12 years ago | on: The Meteoric Rise of DigitalOcean
In that case, check out ToS's on the services you use. They're, suprisingly, usually not that long or hard to read.
kGrange | 12 years ago | on: Don’t Hash Secrets (2008)
But doesn't the attacker only need to rebuild the dictionary once, using the salt they recovered?
kGrange | 12 years ago | on: Firefox OS: System wide orientation lock in 45LOC
From http://ycombinator.com/newsguidelines.html :
Don't abuse the text field in the submission form to add commentary to links. The text field is for starting discussions. If you're submitting a link, put it in the url field. If you want to add initial commentary on the link, write a blog post about it and submit that instead.
kGrange | 12 years ago | on: The making of Medium.com
It wouldn't be a panacea for bad crypto, and it does create a risk of people thinking "oh, it passed all of the tests, it must be secure," while still implementing it overall incorrectly. But I still think it would mitigate these "foolish/easy" errors and allows devs to focus on proper overall implementation.
Or does something like this already exist?